Privacy Policy

Last Updated: August 13, 2026


1. INTRODUCTION

This Privacy Policy is published by PROJX APP HOLDINGS LLC, a Florida limited liability company in good standing, the operator of the PROJX App under an exclusive worldwide license from PROJX PLATFORMS LLC and the counterparty responsible for operations, payments, ticketing, support, and user contracts (referred to
below as "PROJX APP HOLDINGS LLC," "we," "us," or "our") — the legal entity
that operates the PROJX App (under an exclusive license from
PROJX PLATFORMS LLC, the owner of the App's intellectual property) and
that is the data controller for the personal information
described here. PROJX PLATFORMS LLC does not collect, store, or process
user personal data. It
explains what data the App collects, how we use, encrypt, and
protect it, and the choices you have. By using the App you agree
to this Policy. The Terms of Service (a separate document)
governs your use of the App generally; this Policy governs
data only.


2. INFORMATION WE COLLECT

2.1 Information You Provide.
  - Account: name, username, email, phone number, profile photo,
    date of birth, social-handle links you choose to add.
  - Payments: payment-method tokens collected and processed by
    Stripe (we do not store full card numbers); ticket-purchase
    history; tap-to-pay transactions.
  - Content: videos, photos, comments, chat messages, livestream
    recordings, music requests, event posts.
  - Communications: messages and customer-support inquiries you
    send us.
  - Verification: phone-OTP confirmations, optional ID for hosts /
    verified accounts.
  - Identity / age verification (optional "Verify ID" feature):
    if you choose to verify, Stripe Identity — not us — collects
    and processes your government-ID images and selfie. WE NEVER
    RECEIVE OR STORE YOUR ID PHOTOS OR SELFIE. From the verified
    result we store only: a verification status, whether you are
    over 18 / over 21, and your verified date of birth, which we
    use to compute your age against an event's age requirement
    (e.g., 18+/21+ doors) including at ticket scanning. Stripe's
    processing is governed by Stripe's privacy policy.

2.2 Information Collected Automatically.
  - Device: model, OS version, locale, time zone, push token,
    app version, IP address, crash logs.
  - Usage analytics: screen views, button taps, video views,
    session duration, feature usage. We use this for product
    improvement and personalization.
  - Location: approximate (and, with permission, precise)
    location for nearby-event discovery and the map — including,
    if you use the "My Car" feature, the parking spot you save
    (stored on your profile until you remove it) and, if you
    enable location sharing, your last shared position shown to
    mutual friends.
  - Cookies / similar technologies on the web app.
  - Account-security and enforcement records. To keep suspended
    accounts suspended and to detect attempts to evade a
    suspension, we automatically collect and retain:
      (a) the IP address your device connects from, together with
          the approximate network type (for example, home or
          office broadband, or mobile carrier network), and the
          date and time of each session;
      (b) a history of the IP addresses associated with your
          account over time;
      (c) if an account has been suspended, a record of each
          later attempt to sign in or create an account using
          that account's phone number or email address, or from
          a network associated with it — including the phone
          number or email address entered, the IP address used,
          the device's browser/app identifier, and the exact date
          and time of the attempt.
    We collect (c) even where the attempt is refused and no
    account is created, because the record of the attempt is the
    only way we can identify and act on evasion. We do not use
    any of this information for advertising, personalization, or
    profiling, and we do not sell or share it. See section 5 for
    how long we keep it.

2.3 Information from Third Parties.
  - Sign-in providers (Google, Apple, Facebook) when you choose
    that login path.
  - Stripe (for payment status), Twilio (for SMS receipts), Expo
    Push / APNs / FCM (for delivery receipts), Sentry (for crash
    reports).
  - Contact-list matches when you grant Contacts permission, used
    only to surface friends already on PROJX and to power the
    Invite flow.
  - Spotify (optional "Connect Spotify" feature): with your
    OAuth consent we receive your top artists and saved tracks,
    from which we keep ONLY artist names/IDs and genres — never
    your listening history, playlists' contents, or Spotify
    credentials. We use these markers to personalize event
    recommendations and to build AGGREGATED regional music-demand
    statistics (e.g., "house is trending in your city") that
    cannot reasonably identify you. You can disconnect Spotify
    at any time, which stops further collection.


3. HOW WE USE YOUR INFORMATION

  - Operate, maintain, and improve the App.
  - Personalize the For You feed, Parties feed, and Inbox.
  - Process ticket purchases, refunds, payouts, and rewards.
  - Detect and prevent fraud, abuse, and security incidents.
  - Enforce account suspensions, including detecting and blocking
    attempts to evade a suspension by signing in or registering
    with a different phone number, email address, or network. We
    do this to protect other users and the integrity of the
    platform; it is not used for advertising or personalization.
  - Send you product updates, transactional emails, push
    notifications, and (with consent where required) marketing.
  - Comply with legal obligations and respond to lawful requests.
  - Run analytics to measure feature usage, A/B tests, and
    business metrics. WE TRACK ANALYTICS AGGRESSIVELY TO IMPROVE
    PRODUCT QUALITY FOR EACH USER. Analytics never sell your
    identity to advertisers; see Section 5.


4. HOW WE SHARE YOUR INFORMATION

  - With your followers / mutuals when you publish content.
  - With third-party hosts when you purchase a ticket to their
    event (name, contact info as required for the event).
  - With service providers (Firebase, Stripe, Twilio, Expo, Sentry,
    Algolia, Cloudflare, etc.) who process data on our behalf
    under written contracts that limit their use to providing
    services to us.
  - In response to legal process (subpoena, court order, or
    where required by law) or to protect rights, safety, and
    property.
  - In a merger, acquisition, financing, or sale of assets, in
    which case the acquirer assumes the obligations of this Policy.
  - With your consent, in any other case.

WE DO NOT SELL YOUR PERSONAL INFORMATION FOR MONEY. We may share
de-identified or aggregated data that cannot reasonably identify
you.

MOBILE INFORMATION AND THIRD-PARTY SHARING: No mobile
information will be shared with third parties/affiliates for
marketing/promotional purposes. All the above categories exclude
text messaging originator opt-in data and consent; this
information will not be shared with any third parties.


5. ANALYTICS, ADS, AND INTEREST-BASED PERSONALIZATION

We use analytics SDKs (Firebase Analytics, Sentry, internal
event-logging) to measure feature usage, performance, retention,
and growth. We may use de-identified analytics to train
recommendation and ranking models. You may opt out of certain
analytics via your device settings (iOS: Limit Ad Tracking; Android:
Reset Advertising ID).


6. DATA SECURITY — 24/7 PROTECTION

We protect your data with industry-standard safeguards, including:
  - TLS / HTTPS in transit for all client / server traffic.
  - Encryption at rest for Firestore, Cloud Storage, and Stripe
    PCI-scope data.
  - Firestore security rules enforcing per-user read/write scope
    on every collection.
  - Server-side rate limiting and Cloudflare Turnstile for abuse
    prevention. Turnstile verifies that traffic comes from real
    people and may run in an invisible mode with no visible
    challenge. Cloudflare processes the limited device and
    interaction signals needed for this check as described in
    Cloudflare's Privacy Policy and the Cloudflare Turnstile
    Privacy Addendum
    (https://www.cloudflare.com/turnstile-privacy-policy/).
    Turnstile does not serve ads and is not used for cross-site
    tracking.
  - Device-integrity checks (jailbreak / root / emulator
    detection) and Firebase App Check attestation on the mobile
    app, with certificate-pinning controls for sensitive API
    traffic.
  - Sensitive secrets stored in iOS Keychain / Android Keystore
    via SecureStore (NOT AsyncStorage).
  - 24/7 monitoring via Sentry + log aggregation; on-call rotation
    for security incidents.

NO SYSTEM IS COMPLETELY SECURE. While we use commercially
reasonable efforts, we do not warrant that your information will
never be accessed by an unauthorized party. You are responsible
for keeping your account credentials confidential.


7. YOUR PRIVACY RIGHTS

Depending on where you live, you may have the following rights:
  - Access the personal data we hold about you.
  - Correct inaccurate data.
  - Delete your data ("right to be forgotten") subject to legal
    retention obligations.
  - Object to or restrict certain processing.
  - Data portability.
  - Withdraw consent for processing that relies on consent.
  - For California residents (CCPA / CPRA): the right to know,
    delete, correct, and limit use of sensitive personal data,
    plus the right not to be discriminated against for exercising
    these rights.
  - For EEA / UK residents (GDPR): the rights above plus the
    right to lodge a complaint with your supervisory authority.

To exercise any of these rights, contact us via the support
address listed below. We may verify your identity before acting
on a request.


8. CHILDREN'S PRIVACY

The App is not directed to children under 13. We do not knowingly
collect personal data from children under 13. If you believe a
child has provided us with personal data, contact us and we will
delete it.


9. INTERNATIONAL DATA TRANSFERS

We process data in the United States. If you access the App from
outside the U.S., you consent to the transfer of your data to the
U.S. We use Standard Contractual Clauses or other lawful
mechanisms where required.


10. RETENTION

We retain personal data for as long as your account is active,
plus a reasonable period thereafter for legal, tax, fraud-
prevention, and dispute-resolution purposes. Backup copies may
persist for additional time per our backup-rotation schedule.

Account-security and enforcement records (Section 2.2) are kept
on a separate schedule, because they only do their job over time:

  - IP address history for an account in good standing: retained
    while the account is active and for 12 months afterwards.
  - Records relating to a SUSPENDED account, including refused
    sign-in and registration attempts and the networks they came
    from: retained for as long as the suspension is in force, and
    for 24 months after it is lifted or the account is deleted.

We keep the suspended-account records after deletion for one
reason: a suspension that is erased the moment the account is
deleted can be escaped by deleting the account. If a suspension
is lifted, the identifiers are removed from the block list
immediately, so you are no longer prevented from signing in.


11. CHANGES TO THIS POLICY

We may update this Policy. The "Last Updated" date at the top
will reflect the most recent change. For material changes, we
will surface an in-app re-acceptance prompt. Your continued use
of the App after the effective date constitutes acceptance.


12. ANTI-SCRAPING AND ANTI-PROXY DATA COLLECTION

12.1 Authorized Use Only. The data displayed inside PROJX —
including but not limited to user profiles, posts, video and
image content, comments, ranking and recommendation outputs,
event listings, prices, attendee counts, ticket inventory,
rewards balances, anti-fraud signals, search results, the
visual design and code of the App, and any analytics or
metrics surfaced in-app — is provided to you for your personal,
in-app use only. It is NOT licensed for extraction, copying,
republication, modeling, training, or any commercial purpose.

12.2 No Scraping. You may not, and you may not authorize,
permit, instruct, hire, contract with, or assist any third
party to:
  (a) crawl, scrape, harvest, mirror, or systematically copy
      any portion of the App's data, content, or interfaces;
  (b) use any bot, script, automated tool, headless browser,
      reverse-proxy, MITM proxy, packet sniffer, or AI agent
      to access the App or its data;
  (c) bypass, circumvent, or attempt to defeat any rate limit,
      authentication check, security control, robots directive,
      Cloudflare Turnstile, app-attest signal, certificate
      pin, or other technical measure protecting the App;
  (d) train, fine-tune, distill, or otherwise build any
      machine-learning model on data extracted from the App
      (including ranking outputs, recommendation outputs, and
      generated text/audio/video).

12.3 Anti-Proxy Clause — No Use of Third Parties or Friends.
For the avoidance of doubt: instructing, hiring, paying,
asking, or otherwise inducing any third party — INCLUDING but
not limited to a friend, family member, contractor, employee
of a competitor, intermediary, data broker, scraper-as-a-
service vendor, AI agent, or anonymous account — to do any of
the things prohibited in Section 12.2 on your behalf, or to
share with you data they obtained that way, is treated
identically to doing it yourself. You remain fully and
personally liable, jointly and severally with the third party,
for the conduct AND for the resulting damages. Acting through
a proxy is NOT a loophole.

12.4 Competitor-Specific Application. The prohibitions above
apply to ALL users, but they apply with particular force to
users affiliated — directly or indirectly — with a business
that competes with PROJX APP HOLDINGS LLC in ticketing, social video,
party / nightlife, creator-rewards, or any adjacent vertical.
Competitor-affiliated users may NOT use the App to research,
benchmark, model, or develop a competing product. The
contractual restrictions in this Section 12 are in addition
to (not in lieu of) the platform restrictions and remedies in
Sections 7, 9, and 10 of the Terms of Service.

12.5 Remedies for Violation. Violation of this Section 12 is a
material breach of both this Privacy Policy and the Terms of
Service. PROJX APP HOLDINGS LLC may pursue all remedies available at law
and in equity, including without limitation: account
termination; injunctive relief without bond; statutory damages
under the Computer Fraud and Abuse Act (18 U.S.C. § 1030),
the Defend Trade Secrets Act, the Digital Millennium Copyright
Act anti-circumvention provisions (17 U.S.C. § 1201), state
unfair-competition and computer-trespass statutes, and the
Lanham Act; recovery of profits unjustly earned from the
extracted data; and recovery of our reasonable attorney's fees
and costs. By using the App you agree that monetary damages
alone are inadequate to remedy a Section 12 breach and that
PROJX APP HOLDINGS LLC is entitled to immediate equitable relief.


13. CONTACT

Questions or requests about this Privacy Policy or your data?
Contact the data controller:

  PROJX APP HOLDINGS LLC
  7901 4th St N, STE 300
  St. Petersburg, FL 33702
  Email: prince@projx.app

© 2026 PROJX PLATFORMS LLC. All rights reserved. PROJX is
operated by PROJX APP HOLDINGS LLC under exclusive license from
PROJX PLATFORMS LLC.